- Database protocol exploits explained
- Review: MXI M700 Bio
- Measuring web application security coverage
- Inside backup and storage: The expert's view
- Combating the changing nature of online fraud
- Book review: CISSP Study Guide
- Successful data security programs encompass processes, people, technology
- Sangria, tapas and hackers: SOURCE Barcelona 2010
- What CSOs can learn from college basketball
- Network troubleshooting 101
- America’s cyber cold war
- RSA Conference Europe 2010
- Book review: Dissecting the Hack: The F0rb1dd3n Network (Revised Edition)
- Bootkits – a new stage of development
Mostrando entradas con la etiqueta Revistas y Magazines. Mostrar todas las entradas
Mostrando entradas con la etiqueta Revistas y Magazines. Mostrar todas las entradas
jueves, 18 de noviembre de 2010
Revistas y Magazines
0
comentarios
Número 28 de la revista (In)Secure Magazine
Los contenidos de este ejemplar son:
Se acabó el verano y toca volver a la carga. Este primer post postvacacional es ligeríto y referencio el nuevo número de la revista Insecure Magazine que trae estos contenidos:

La descarga puede obtenerse en este enlace.
Solo quiero agradecer a los casi ya 4.500 lectores vuestro tiempo al dedicar a mi blog un rato de vuestras vidas. Es un soplo que motiva a continuar día a día con el pequeño esfuerzo de buscar aquellas cosas que puedan ser de interés para todos vosotros. Espero y quiero, a pesar de que ello disminuya en parte la frecuencia de publicación, aportar más reflexiones y opiniones sobre la gestión de la seguridad de la información.
Un saludo y mil gracias.
- Review: BlockMaster SafeStick secure USB flash drive
- The devil is in the details: Securing the enterprise against the cloud
- Cybercrime may be on the rise, but authentication evolves to defeat it
- Learning from bruteforcers
- PCI DSS v1.3: Vital to the emerging demand for virtualization and cloud security
- Security testing - the key to software quality
- A brief history of security and the mobile enterprise
- Payment card security: Risk and control assessments
- Security as a process: Does your security team fuzz?
- Book review: Designing Network Security, 2nd Edition
- Intelligent security: Countering sophisticated fraud
La descarga puede obtenerse en este enlace.
Solo quiero agradecer a los casi ya 4.500 lectores vuestro tiempo al dedicar a mi blog un rato de vuestras vidas. Es un soplo que motiva a continuar día a día con el pequeño esfuerzo de buscar aquellas cosas que puedan ser de interés para todos vosotros. Espero y quiero, a pesar de que ello disminuya en parte la frecuencia de publicación, aportar más reflexiones y opiniones sobre la gestión de la seguridad de la información.
Un saludo y mil gracias.
Los contenidos de este número incluyen:

Podéis descargarla en este enlace.
- The changing face of penetration testing: Evolve or die!
- Review: SmartSwipe
- Unusual SQL injection vulnerabilities and how to exploit them
- Take note of new data notification rules
- RSA Conference 2010 coverage
- Corporate monitoring: Addressing security, privacy, and temptation in the workplace
- Cloud computing and recovery, not just backup
- EJBCA: Make your own certificate authority
- Advanced attack detection using OSSIM
- The world of claims-based security
- Enterprise Authentication: Increasing security without breaking the bank

Podéis descargarla en este enlace.
Ya está disponible el número 23 de la revista (IN)Secure Magazine. Los contenidos de este número son:
- Microsoft's security patches year in review: A malware researcher's
perspective
- A closer look at Red Condor Hosted Service
- Report: RSA Conference Europe 2009, London
- The U.S. Department of Homeland Security has a vision for stronger
information security
- Q&A: Didier Stevens on malicious PDFs
- Protecting browsers, endpoints and enterprises against new Web-based
attacks
- Mobile spam: An old challenge in a new guise
- Report: BruCON security conference, Brussels
- Are you putting your business at risk?
- Why out-of-band transactions verification is critical to protecting
online banking
- Study uncovers alarming password usage behavior
- Q&A: Noise vs. Subversive Computing with Pascal Cretain
- Elevating email to an enterprise-class database application solution
- Ask the social engineer: Practice
- Report: Storage Expo 2009, London
- Jumping fences - the ever decreasing perimeter

La revista puede obtenerse aquí.
- Microsoft's security patches year in review: A malware researcher's
perspective
- A closer look at Red Condor Hosted Service
- Report: RSA Conference Europe 2009, London
- The U.S. Department of Homeland Security has a vision for stronger
information security
- Q&A: Didier Stevens on malicious PDFs
- Protecting browsers, endpoints and enterprises against new Web-based
attacks
- Mobile spam: An old challenge in a new guise
- Report: BruCON security conference, Brussels
- Are you putting your business at risk?
- Why out-of-band transactions verification is critical to protecting
online banking
- Study uncovers alarming password usage behavior
- Q&A: Noise vs. Subversive Computing with Pascal Cretain
- Elevating email to an enterprise-class database application solution
- Ask the social engineer: Practice
- Report: Storage Expo 2009, London
- Jumping fences - the ever decreasing perimeter

La revista puede obtenerse aquí.
Ya se ha publicado el Número 22 de la Revista Insecure Magazine.

Los contenidos de este ejemplar son:
Podéis descargar la revista en este enlace.

Los contenidos de este ejemplar son:
- Using real-time events to drive your network scans
- The Nmap project: Open source with style
- A look at geolocation, URL shortening and top Twitter threats
- Review: Data Locker
- Making clouds secure
- Top 5 myths about wireless protection
- Securing the foundation of IT systems
- Is your data recovery provider a data security problem?
- Security for multi-enterprise applications
- In mashups we trust?
Podéis descargar la revista en este enlace.
Ya se ha publicado el número 20 de la revista (IN)Secure Magazine. Los contenidos de este número son:
The covered topics include:
- Improving network discovery mechanisms
- Building a bootable BackTrack 4 thumb drive with persistent changes and Nessus
- Review: SanDisk Cruzer Enterprise
- Forgotten document of American history offers a model for President Obama's vision of government information technology
- Security standpoint by Sandro Gauci: The year that Internet security failed
- What you need to know about tokenization
- Q&A: Vincenzo Iozzo on Mac OS X security
- Book review - Hacking VoIP: Protocols, Attacks and Countermeasures
- A framework for quantitative privacy measurement
- Why fail? Secure your virtual assets
- Q&A: Scott Henderson on the Chinese underground
- iPhone security software review: Data Guardian
- Phased deployment of Network Access Control
- Playing with authenticode and MD5 collisions
- Web 2.0 case studies: challenges, approaches and vulnerabilities
- Q&A: Jason King, CEO of Lavasoft
- Book review - Making Things Happen: Mastering Project Management
- ISP level malware filtering
- The impact of the consumerization of IT on IT security management
The covered topics include:
- Improving network discovery mechanisms
- Building a bootable BackTrack 4 thumb drive with persistent changes and Nessus
- Review: SanDisk Cruzer Enterprise
- Forgotten document of American history offers a model for President Obama's vision of government information technology
- Security standpoint by Sandro Gauci: The year that Internet security failed
- What you need to know about tokenization
- Q&A: Vincenzo Iozzo on Mac OS X security
- Book review - Hacking VoIP: Protocols, Attacks and Countermeasures
- A framework for quantitative privacy measurement
- Why fail? Secure your virtual assets
- Q&A: Scott Henderson on the Chinese underground
- iPhone security software review: Data Guardian
- Phased deployment of Network Access Control
- Playing with authenticode and MD5 collisions
- Web 2.0 case studies: challenges, approaches and vulnerabilities
- Q&A: Jason King, CEO of Lavasoft
- Book review - Making Things Happen: Mastering Project Management
- ISP level malware filtering
- The impact of the consumerization of IT on IT security management
Ya se ha publicado el número 19 de la revista (In)Secure Magazine. En este número, se tratan los siguientes contenidos:

El número puede ser descargado en el siguiente enlace.
- The future of AV: looking for the good while stopping the bad
- Eight holes in Windows login controls
- Extended validation and online security: EV SSL gets the green light
- Interview with Giles Hogben, an expert on identity and authentication technologies working at ENISA
- Web filtering in a Web 2.0 world
- RSA Conference Europe 2008
- The role of password management in compliance with the data protection act
- Securing data beyond PCI in a SOA environment: best practices for advanced data protection
- Three undocumented layers of the OSI model and their impact on security
- Interview with Rich Mogull, founder of Securosis

El número puede ser descargado en el siguiente enlace.
jueves, 25 de septiembre de 2008
Revistas y Magazines
0
comentarios
Revista (IN)Secure Magazine nº18
Ya se ha publicado el número 18 de la revista (IN)Secure Magazine. Los contenidos de esta edición son:

Podéis descargar el ejemplar pulsando aquí.

- Network and information security in Europe today
- Browser security: bolt it on, then build it in
- Passive network security analysis with NetworkMiner
- Lynis - an introduction to UNIX system auditing
- Windows driver vulnerabilities: the METHOD_NEITHER odyssey
- Removing software armoring from executables
- Insecurities in privacy protection software
- Compliance does not equal security but it's a good start
- Secure web application development
- The insider threat
- Web application security: risky business?
Podéis descargar el ejemplar pulsando aquí.
De nuevo la revista (IN)secure Magazine viene cargada de contenidos en su número 17. Los temas que se tratan en este ejemplar son:
- Security standpoint by Sandro Gauci: when best intentions go wrong
- Review: Red Condor Hosted Service
- Reverse engineering software armoring (part 1)
- Security training and awareness: strengthening your weakest link
- Hacking Second Life
- Building a secure wireless network for under $300
- Assessing risk in VoIP/UC networks
- Open redirect vulnerabilities: definition and prevention
- Migration from e-mail to web borne threats
- Bypassing and enhancing live behavioral protection
- Point security solutions are not a 4 letter word
- The future of security is information-centric
- Corporate due diligence in India: an ICT perspective
- E-mail encryption service: a smart choice for SMBs
- Securing the enterprise data flow against advanced attacks
- How to prevent identity theft
- Security flaws identification and technical risk analysis through threat modeling

Podéis descargarlo pulsando (IN)Secure Magazine Número 17.
- Security standpoint by Sandro Gauci: when best intentions go wrong
- Review: Red Condor Hosted Service
- Reverse engineering software armoring (part 1)
- Security training and awareness: strengthening your weakest link
- Hacking Second Life
- Building a secure wireless network for under $300
- Assessing risk in VoIP/UC networks
- Open redirect vulnerabilities: definition and prevention
- Migration from e-mail to web borne threats
- Bypassing and enhancing live behavioral protection
- Point security solutions are not a 4 letter word
- The future of security is information-centric
- Corporate due diligence in India: an ICT perspective
- E-mail encryption service: a smart choice for SMBs
- Securing the enterprise data flow against advanced attacks
- How to prevent identity theft
- Security flaws identification and technical risk analysis through threat modeling

Podéis descargarlo pulsando (IN)Secure Magazine Número 17.
martes, 22 de abril de 2008
Revistas y Magazines
0
comentarios
Revista (In)secure Magazine, número 16
Ya está accesible el número 16 de la revista (In)secure Magazine. Los contenidos de este ejemplar son:
- Security policy considerations for virtual worlds
- US political elections and cybercrime
- Using packet analysis for network troubleshooting
- The effectiveness of industry certifications
- Building a secure future: lessons learned from 2007's highest-
profile security events
- Advanced social engineering and human exploitation, part 2
- Interview with Nitesh Dhanjani, Senior Manager at Ernst & Young
- Is your data safe? Secure your web apps
- RSA Conference 2008
- Producing secure software with security enhanced software
development processes
- Network event analysis with Net/FSE
- Security risks for mobile computing on public WLANs: hotspot
registration
- Black Hat Europe 2008 Briefings & Training
- A Japanese perspective on Software Configuration Management
- Windows log forensics: did you cover your tracks?
- Traditional vs. non-tranditional database auditing
- Payment card data: know your defense options
El documento está accesible en Numero 16 (In)secure Magazine.
- Security policy considerations for virtual worlds
- US political elections and cybercrime
- Using packet analysis for network troubleshooting
- The effectiveness of industry certifications
- Building a secure future: lessons learned from 2007's highest-
profile security events
- Advanced social engineering and human exploitation, part 2
- Interview with Nitesh Dhanjani, Senior Manager at Ernst & Young
- Is your data safe? Secure your web apps
- RSA Conference 2008
- Producing secure software with security enhanced software
development processes
- Network event analysis with Net/FSE
- Security risks for mobile computing on public WLANs: hotspot
registration
- Black Hat Europe 2008 Briefings & Training
- A Japanese perspective on Software Configuration Management
- Windows log forensics: did you cover your tracks?
- Traditional vs. non-tranditional database auditing
- Payment card data: know your defense options
El documento está accesible en Numero 16 (In)secure Magazine.
Ya ha sido publicado el número de febrero de la revista (In)secure Magazine. Los contenidos de este ejemplar son:

El ejemplar puede ser descargado directamente en este enlace.

- Proactive analysis of malware genes holds the key to network security
- Advanced social engineering and human exploitation
- Free visualization tools for security analysis and network monitoring
- Internet terrorist: does such a thing really exist?
- Weaknesses and protection of your wireless network
- Fraud mitigation and biometrics following Sarbanes-Oxley
- Application security matters: deploying enterprise software securely
- The insider threat: hype vs. reality
- How B2B gateways affect corporate information security
- Reputation attacks, a little known Internet threat
- Data protection and identity management
- The good, the bad and the ugly of protecting data in a retail environment
- Malware experts speak: F-Secure, Sophos, Trend Micro
El ejemplar puede ser descargado directamente en este enlace.
Ya ha sido publicado el número 11 de la revista (In)secure Magazine. Los contenidos de este número son:

La revista está descargable en:
(IN)SECURE Magazine número 11
- On the security of e-passports
- Review: GFI LANguard Network Security Scanner 8
- Critical steps to secure your virtualized environment
- Interview with Howard Schmidt, President and CEO R & H Security Consulting
- Quantitative look at penetration testing
- Integrating ISO 17799 into your Software Development Lifecycle
- Public Key Infrastructure (PKI): dead or alive?
- Interview with Christen Krogh, Opera Software's Vice President of Engineering
- Super ninja privacy techniques for web application developers
- Security economics
- iptables - an introduction to a robust firewall
- Black Hat Briefings & Training Europe 2007
- Enforcing the network security policy with digital certificates

La revista está descargable en:
(IN)SECURE Magazine número 11
Ha sido publicado el número 10 de la revista (In)secure Magazine. El contenido de este número es:
- Microsoft Windows Vista: significant security improvement?
- Review: GFI Endpoint Security 3
- Interview with Edward Gibson, Chief Security Advisor at Microsoft UK
- Top 10 spyware of 2006
- The spam problem and open source filtering solutions
- Office 2007: new format and new protection/security policy
- Wardriving in Paris
- Interview with Joanna Rutkowska, security researcher
- Climbing the security career mountain: how to get more than just a job
- RSA Conference 2007 report
- ROT13 is used in Windows? You're joking!
- Data security beyond PCI compliance - protecting sensitive data in a distributed environment
La revista puede ser descargada desde el siguiente enlace: Insecure Magazine número 10
- Microsoft Windows Vista: significant security improvement? - Review: GFI Endpoint Security 3
- Interview with Edward Gibson, Chief Security Advisor at Microsoft UK
- Top 10 spyware of 2006
- The spam problem and open source filtering solutions
- Office 2007: new format and new protection/security policy
- Wardriving in Paris
- Interview with Joanna Rutkowska, security researcher
- Climbing the security career mountain: how to get more than just a job
- RSA Conference 2007 report
- ROT13 is used in Windows? You're joking!
- Data security beyond PCI compliance - protecting sensitive data in a distributed environment
La revista puede ser descargada desde el siguiente enlace: Insecure Magazine número 10
Ya se ha publicado el número de enero del ENISA Quarterly, el boletín de seguridad elaborado por la Agencia Europea de Seguridad. Los artículos de este número son:
- Information Security and Externalities, de Bruce Schneier
- Enabling User Confidence, de Andrew Cormack
- Computer Viruses, de Jaak Akker
- Security and Dependability, de Stephan Lechner y James Clarke
- What can we achieve with Information Security Certification? de Carsten Casper
- ENISA’s Roadmap for Contemporary and Emerging Risks, de Jani Arnell
- ENISA Authentication Language Workshop and Interest Group, de Giles Hogben
- Strategy to Improve Internet Security in Sweden, de Anders Rafting
- e-discussion on e-security in Poland,de Krysztof Silicki y Mirsolaw Maj
Descarga: Enisa Quarterly
La revista (In)secure magazine acaba de publicar su novena edición.
El indice de este número es:
-Effectiveness of security by admonition: a case study of security warnings in a web browser setting
- Web 2.0 defense with AJAX fingerprinting and filtering
- Hack In The Box Security Conference 2006
- Where iSCSI fits in enterprise storage networking
- Recovering user passwords from cached domain records
- Do portable storage solutions compromise business security?
- Enterprise data security - a case study
- Creating business through virtual trust: how to gain and sustain a competitive advantage using information security
El indice de este número es:-Effectiveness of security by admonition: a case study of security warnings in a web browser setting
- Web 2.0 defense with AJAX fingerprinting and filtering
- Hack In The Box Security Conference 2006
- Where iSCSI fits in enterprise storage networking
- Recovering user passwords from cached domain records
- Do portable storage solutions compromise business security?
- Enterprise data security - a case study
- Creating business through virtual trust: how to gain and sustain a competitive advantage using information security
miércoles, 6 de septiembre de 2006
Revistas y Magazines
0
comentarios
Revista (In) secure Magazine nº8
Ya se ha publicado el número 8 de la excelente revista (In)secure Magazine.
El contenido de este número de septiembre es (en ingles):

* Payment Card Industry demystified
* Skype: how safe is it?
* Computer forensics vs. electronic evidence
* Review: Acunetix Web Vulnerability Scanner 4.0
* SSH port forwarding - security from two perspectives, part two
* Log management in PCI compliance
* Airscanner vulnerability summary: Windows Mobile security software fails the test
* Proactive protection: a panacea for viruses?
* Introducing the MySQL Sandbox
* Continuous protection of enterprise data: a comprehensive approach
El contenido de este número de septiembre es (en ingles):

* Payment Card Industry demystified
* Skype: how safe is it?
* Computer forensics vs. electronic evidence
* Review: Acunetix Web Vulnerability Scanner 4.0
* SSH port forwarding - security from two perspectives, part two
* Log management in PCI compliance
* Airscanner vulnerability summary: Windows Mobile security software fails the test
* Proactive protection: a panacea for viruses?
* Introducing the MySQL Sandbox
* Continuous protection of enterprise data: a comprehensive approach
El contenido de este número es:- SSH port forwarding: security from two perspectives, part one An inside job
- CEO spotlight: Q&A with Patricia Sueltz, SurfControl
- Server monitoring with munin and monit
- Compliance vs. awareness in 2006
- Infosecurity 2006
- 2005 *nix malware evolution
- InfoSec World 2006
- Overview of quality security podcasts
miércoles, 5 de abril de 2006
Noticias,
Revistas y Magazines
0
comentarios
Numero 6 de (In)secure Magazine
Indice:Best practices in enterprise database protection
Quantifying the cost of spyware to the enterprise
Security for websites - breaking sessions to hack into a machine
How to win friends and influence people with IT security certifications
The size of security: the evolution and history of OSSTMM operational security metrics
Interview with Kenny Paterson, Professor of Information Security at Royal Holloway, University of London
PHP and SQL security today
Apache security: Denial of Service attacks
War-driving in Germany - CeBIT 2006
domingo, 6 de noviembre de 2005
Noticias,
Revistas y Magazines
0
comentarios
Numero 4 de (In)secure Magazine.
viernes, 16 de septiembre de 2005
Noticias,
Revistas y Magazines
1 comentarios
Revista (In)secure Magazine
Llevo meses sin referenciar fuentes interesantes respecto a la seguridad y de las que conviene estar al tanto. Hoy voy a comentar la revista (In)secure magazine, que es una revista de seguridad informatica en formato electrónico y que puede ser descargada desde http://www.insecuremagazine.com/.
Lo más recomendable es estar informado via RSS pero dado que es una publicación que acaba de empezar y con una periodicidad de 2 meses, solo hay que acordarse cuando toca.
Los tres numeros publicados hasta la fecha son:
- Número 3.Agosto.

- Número 2.Junio.

- Número 1.Abril.
Lo más recomendable es estar informado via RSS pero dado que es una publicación que acaba de empezar y con una periodicidad de 2 meses, solo hay que acordarse cuando toca.
Los tres numeros publicados hasta la fecha son:
- Número 3.Agosto.
- Número 2.Junio.
- Número 1.Abril.
Suscribirse a:
Entradas (Atom)




- Follow Us on Twitter!
- "Join Us on Facebook!
- RSS
Contacta por Linkedin